Type Confusion in .NET and Visual Studio - CVE-2024-43498
Published: November 12, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a type confusion error in .NET and Visual Studio. A remote attacker can pass specially crafted request to the application, trigger a type confusion error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Visual Studio
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Fedora
aspnetcore-runtime-9.0 (Ubuntu package)
dotnet-host-9.0 (Ubuntu package)
dotnet-hostfxr-9.0 (Ubuntu package)
dotnet-runtime-9.0 (Ubuntu package)
dotnet-sdk-9.0 (Ubuntu package)
dotnet-sdk-aot-9.0 (Ubuntu package)
dotnet9.0 (Red Hat package)
dotnet9.0
dotnet9 (Ubuntu package)
How to mitigate CVE-2024-43498
dotnet-host-9.0 (Ubuntu package) - update to 9.0.0-rtm-0ubuntu1~24.10.1
dotnet-hostfxr-9.0 (Ubuntu package) - update to 9.0.0-rtm-0ubuntu1~24.10.1
dotnet-runtime-9.0 (Ubuntu package) - update to 9.0.0-rtm-0ubuntu1~24.10.1
dotnet-sdk-9.0 (Ubuntu package) - update to 9.0.100-rtm-0ubuntu1~24.10.1
dotnet-sdk-aot-9.0 (Ubuntu package) - update to 9.0.100-rtm-0ubuntu1~24.10.1
dotnet9.0 (Red Hat package) - update to 9.0.100-1.el9_5
dotnet9.0 - addressed in versions 9.0.100-1.fc40, 9.0.100-1.fc41
dotnet9 (Ubuntu package) - update to 9.0.100-9.0.0-0ubuntu1~24.10.1